High severity8.8NVD Advisory· Published Apr 8, 2026· Updated Apr 16, 2026
CVE-2026-27140
CVE-2026-27140
Description
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- pkg.go.dev/vuln/GO-2026-4871nvdVendor Advisory
- go.dev/cl/763768nvdRelease Notes
- go.dev/issue/78335nvdIssue Tracking
- groups.google.com/g/golang-announce/c/0uYbvbPZRWUnvdRelease NotesMailing List
News mentions
0No linked articles in our index yet.